The censorship attack is ubiquitous in prevailing blockchains, such as Bitcoin and Ethereum, yet has not been resolved well so far. According to known vulnerabilities of different consensus algorithms, censorship attacks can always achieve great benefits at low costs by various means. In this paper, we propose improvements to existing POS and POW algorithms to resolve censorship attacks in two methods. The first method improves the Tendermint consensus mechanism by introducing three new types of messages and an auxiliary role of network nodes. The method can automatically defend against censorship attacks and organize an honest chain. The second method is based on the CasperFFG consensus mechanism and can accurately identify the attackers by evaluating the suspicious scores of all validators. However, an honest validator has to manually choose the honest chain. Theoretical analyses show their effectiveness.
Online advertising is a popular business model where advertisers can deliver promotional marketing messages to their potential consumers via Ad brokers. However, as the proxy between advertisers and customers, a malicious Ad broker could arbitrarily fabricate the advertising rates to overcharge advertisers, which causes unnecessary financial loss. To deal with this issue, we propose a publicly verifiable and fair online advertising scheme. Specifically, a proof-of-downloading (PoD) protocol is first designed based on the zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK), to help the customer generate a unique acknowledgment for downloading the Ad; the acknowledgment will then be published to both the advertiser and the Ad broker such that anyone can verify the acknowledgment to guarantee the fairness and transparency of online advertising. Moreover, as long as the customer's private key is not leaked, our scheme can resist the collusion attack, i.e., the Ad broker and the customer collude with each other to deceive the advertiser, which has not been addressed in previous works. Finally, we evaluate the performance of the proposed scheme to demonstrate its computational efficiency.
Following Bitcoin's Nakamoto Consensus protocol (NC), hundreds of cryptocurrencies utilize proofs of work (PoW) to maintain their ledgers. However, research shows that NC fails to achieve perfect chain quality, allowing malicious miners to alter the public ledger in order to launch several attacks, i.e., selfish mining, double-spending and feather-forking. Some later designs, represented by Ethereum, Bitcoin-NG, DECOR+, Byzcoin and Publish or Perish, aim to solve the problem by raising the chain quality; other designs, represented by Fruitchains, DECOR+ and Subchains, claim to successfully defend against the attacks in the absence of perfect chain quality. As their effectiveness remains self-claimed, the community is divided on whether a secure PoW protocol is possible. In order to resolve this ambiguity and to lay down the foundation of a common body of knowledge, this paper introduces a multi-metric evaluation framework to quantitatively analyze PoW protocols' chain quality and attack resistance. Subsequently we use this framework to evaluate the security of these improved designs through Markov decision processes. We conclude that to date, no PoW protocol achieves ideal chain quality or is resistant against all three attacks. We attribute existing PoW protocols' imperfect chain quality to their unrealistic security assumptions, and their unsatisfactory attack resistance to a dilemma between "rewarding the bad" and "punishing the good". Moreover, our analysis reveals various new protocol-specific attack strategies. Based on our analysis, we propose future directions toward more secure PoW protocols and indicate several common pitfalls in PoW security analyses.
Smart contracts have been widely used on Ethereum to enable business services across various application domains. However, they are prone to different forms of security attacks due to the dynamic and non-deterministic blockchain runtime environment. In this work, we highlighted a general miner-side type of exploit, called concurrency exploit, which attacks smart contracts via generating malicious transaction sequences. Moreover, we designed a systematic algorithm to automatically detect such exploits. In our preliminary evaluation, our approach managed to identify real vulnerabilities that cannot be detected by other tools in the literature.
Many chatbots have been developed that provide a multitude of services through a wide range of methods. A chatbot is a brand-new conversational agent in the highspeed changing technology world. With the advance of Artificial Intelligence and machine learning, chatbots are becoming more and more popular. A chatbot is the extension of human interface mediums such as the phone and social platforms. Similarly, Cryptocurrency is a new extension of digital or virtual currency designed to work as a medium of exchange. In the current digital exchanging world, investors and interested parties are eager to know more information about, and the capabilites of, this new type of currency. One of the potential paths to retrieve the info automatically and quickly is through a chatbot. We explored the open source python library, Chatterbot, to apply Itchat API (a WeChat interface) with the aim of building a robot chatting application, I&C Chat, on the topic of cryptocurrency. First, we collected question and answer pairs datasets from Quora websites. Furthermore, we also created API calls to query the real time quote for the top 25 cryptocurrencies. Then we used the collected data to train our chatbot and implemented a logic adapter to receive the price quote of cryptocurrencies based on the incoming question. The Itchat API method will return the best matched answer to the asking party automatically. The response time of different questions has been investigated. The results imply that this application is quite useful, feasible and beneficial to the digital currency world.
After the meteoric rise in price, and subsequent public interest, of the cryptocurrency Bitcoin, a developing body of work has begun examining its impact on society. In recent months, as Bitcoin's price has rapidly declined, uncertainty and distrust have begun to overshadow early enthusiasm. In this late-breaking work, we investigated one of the largest and most important Bitcoin online communities, the r/Bitcoin Reddit forum. A vocal subgroup of users identify themselves as "true Bitcoiners", and justify their continued devotion to Bitcoin. These subreddit participants explained and justified their trust in Bitcoin in three primary ways: identifying characteristics of beneficial versus harmful Bitcoin users, diminishing the importance of problems, and describing themselves as loyal to Bitcoin over time.
Bitcoin blockchain technology is a distributed ledger of nodes authorizing transactions between anonymous parties. Its key actors are miners using computational power to solve mathematical problems for validating transactions. By sharing blockchain's characteristics, mining is a decentralized, transparent and unregulated practice, less explored in HCI, so we know little about miners' motivations and experiences, and how these may impact on different dimensions of trust. This paper reports on interviews with 20 bitcoin miners about their practices and trust challenges. Findings contribute to HCI theories by extending the exploration of blockchain's characteristics relevant to trust with the competitiveness dimension underpinning the social organization of mining. We discuss the risks of collaborative mining due to centralization and dishonest administrators, and conclude with design implications highlighting the need for tools monitoring the distribution of rewards in collaborative mining, tools tracking data centers' authorization and reputation, and tools supporting the development of decentralized pools.
The 51% attack is a technique which intends to fork a blockchain in order to conduct double-spending. Adversaries controlling more than half of the total hashing power of a network can perform this attack. In a similar way, n confirmation and selfish mining are two attack techniques that comprise a similar strategy to the 51% attack. Due to the immense attacking cost to perform the 51% attack, it was considered very unlikely for a long period. However, in recent times, the attack has befallen at a frequent pace, costing millions of dollars to various cryptocurrencies. The 51% attack strategy varies based upon the adopted consensus mechanism by a particular cryptocurrency, and it enables attackers to double-spend the same crypto-coin, restrict transactions, cancel blocks, and even have full control over the price of a cryptocurrency. A crypto-coin with a low hashing power is always jeopardized by the 51% attack due to the easily attainable hashing. In this paper, we analyze the real impact of the 51% attack, revealing serious weaknesses in consensus protocols that made this attack possible. We discuss the five most advanced protection techniques to prevent this attack and their main limitations. We conclude that in most cases, security techniques fail to provide real protection against the 51% attack because the weaknesses are inherited from the consensus protocols.
This paper presents an empirical analysis of Steemit, a key representative of the emerging incentivized social media platforms over Blockchains, to understand and evaluate the actual level of decentralization and the practical effects of cryptocurrency-driven reward system in these modern social media platforms. Similar to Bitcoin, Steemit is operated by a decentralized community, where 21 members are periodically elected to cooperatively operate the platform through the Delegated Proof-of-Stake (DPoS) consensus protocol. Our study performed on 539 million operations performed by 1.12 million Steemit users during the period 2016/03 to 2018/08 reveals that the actual level of decentralization in Steemit is far lower than the ideal level, indicating that the DPoS consensus protocol may not be a desirable approach for establishing a highly decentralized social media platform. In Steemit, users create contents as posts which get curated based on votes from other users. The platform periodically issues cryptocurrency as rewards to creators and curators of popular posts. Although such a reward system is originally driven by the desire to incentivize users to contribute to high-quality contents, our analysis of the underlying cryptocurrency transfer network on the blockchain reveals that more than 16% transfers of cryptocurrency in Steemit are sent to curators suspected to be bots and also finds the existence of an underlying supply network for the bots, both suggesting a significant misuse of the current reward system in Steemit. Our study is designed to provide insights on the current state of this emerging blockchain-based social media platform including the effectiveness of its design and the operation of the consensus protocols and the reward system.
The rise of ubiquitous deepfakes, misinformation, disinformation, propaganda and post-truth, often referred to as fake news, raises concerns over the role of Internet and social media in modern democratic societies. Due to its rapid and widespread diffusion, digital deception has not only an individual or societal cost (e.g., to hamper the integrity of elections), but it can lead to significant economic losses (e.g., to affect stock market performance) or to risks to national security. Blockchain and other Distributed Ledger Technologies (DLTs) guarantee the provenance, authenticity and traceability of data by providing a transparent, immutable and verifiable record of transactions while creating a peer-to-peer secure platform for storing and exchanging information. This overview aims to explore the potential of DLTs and blockchain to combat digital deception, reviewing initiatives that are currently under development and identifying their main current challenges. Moreover, some recommendations are enumerated to guide future researchers on issues that will have to be tackled to face fake news, disinformation and deepfakes, as an integral part of strengthening the resilience against cyber-threats on today's online media.
Bruno Rodrigues, Lukas Eisenring, Eder J. Scheid, Thomas Bocek · 5 authors
The volume of traffic generated by modern Distributed Denial-of-Service (DDoS) attacks suggests that centralized defenses are not the most effective approach to counter these attacks. An alternative to reduce the burden of detection and mitigation is to combine centralized defense systems, creating a global and cooperative protection system. However, existing approaches suffer from the complexity of deployment and operation across different systems. Blockchains appear in this scenario as an alternative to simplify the exchange of information in a cooperative defense. This work evaluates in both local and global experimentations the performance of the blockchain system proposed in [8] concerning the latency to perform the signaling of blacklisted addresses.
Andreas Gruhler, Bruno Rodrigues, Burkhard Stiller
Distributed Denial-of-Service (DDoS) attacks rise in frequency, diversity, and intensity. Often, centralized defense approaches lack hard- and software capabilities. A cooperative, multi-domain DDoS mitigation system provides defense services on top of an existing, distributed infrastructure. However, participants in these systems lack incentives for cooperation and reputation. Thus, reward systems can fill this gap by providing necessary incentives for cooperation among service providers and consumers. This paper presents the design, implementation, and evaluation of a reputation scheme for the Blockchain Signaling System (BloSS). A smart contract-enabled process automates reputation management to diminish malicious behavior by incentive design. Among other metrics, Beta reputation provides intelligence to identify and reward honest participants.
Muhammad Saad, Jeffrey Spaulding, Laurent Njilla, Charles Kamhoua · 7 authors
In this paper, we systematically explore the attack surface of the Blockchain technology, with an emphasis on public Blockchains. Towards this goal, we attribute attack viability in the attack surface to 1) the Blockchain cryptographic constructs, 2) the distributed architecture of the systems using Blockchain, and 3) the Blockchain application context. To each of those contributing factors, we outline several attacks, including selfish mining, the 51% attack, Domain Name System (DNS) attacks, distributed denial-of-service (DDoS) attacks, consensus delay (due to selfish behavior or distributed denial-of-service attacks), Blockchain forks, orphaned and stale blocks, block ingestion, wallet thefts, smart contract attacks, and privacy attacks. We also explore the causal relationships between these attacks to demonstrate how various attack vectors are connected to one another. A secondary contribution of this work is outlining effective defense measures taken by the Blockchain technology or proposed by researchers to mitigate the effects of these attacks and patch associated vulnerabilities
We performed the first systematic study of a new attack on Ethereum that steals cryptocurrencies. The attack is due to the unprotected JSON-RPC endpoints existed in Ethereum nodes that could be exploited by attackers to transfer the Ether and ERC20 tokens to attackers-controlled accounts. This study aims to shed light on the attack, including malicious behaviors and profits of attackers. Specifically, we first designed and implemented a honeypot that could capture real attacks in the wild. We then deployed the honeypot and reported results of the collected data in a period of six months. In total, our system captured more than 308 million requests from 1,072 distinct IP addresses. We further grouped attackers into 36 groups with 59 distinct Ethereum accounts. Among them, attackers of 34 groups were stealing the Ether, while other 2 groups were targeting ERC20 tokens. The further behavior analysis showed that attackers were following a three-steps pattern to steal the Ether. Moreover, we observed an interesting type of transaction called zero gas transaction, which has been leveraged by attackers to steal ERC20 tokens. At last, we estimated the overall profits of attackers. To engage the whole community, the dataset of captured attacks is released on https://github.com/zjuicsr/eth-honey.
This work proposes an innovative approach, named CapJack, to detect in-browser malicious cryptocurrency mining activities by using the latest CapsNet technology. To the best of our knowledge, this is the first work to introduce CapsNet to the field of malware detection through system behavioral analysis. It is particularly effective to detect malicious miners under multitasking environments where multiple applications run simultaneously. Experimental data show appealing performance of CapJack, with a detection rate of as high as 87% instantly and 99% within a window of 11 seconds.
Today's online review systems (used largely by hospitality services, internet retailers, government services, etc.) are highly centralized and subject to tampering and manipulation. Implementing a decentralized, trustworthy, unbiased and transparent review system is a major challenge. In this paper, we present a solution that utilizes Ethereum Blockchain, Smart Contracts, and IPFS to provide a secure, transparent and trusted platform for an online review system with high integrity and resiliency. We discuss key aspects related to architectural design, interactions between system components, algorithms and logic flow. We also show how we implemented and tested the overall system functionalities. Furthermore, we provide vulnerability analysis of the smart contract code. The full smart contract code was made publicly available at Github.
With the popularity of Bitcoin, a cryptocurrency market emerged. However, because of insufficient supervision, the market attracts scams, for example, pump and dump (P&D) scheme, a famous fraudulent behavior in stock markets, has been found rampant in the market. To help deal with this issue, as a preliminary study, this paper proposes an improved apriori algorithm to detect user groups which may involve in P&D schemes. The validity of the algorithm is verified by using the leaked transaction history of Mt. Gox Bitcoin exchange. Furthermore, by exploring some of the detected user groups, many abnormal trading behaviors in the exchange found. These findings provide new insights into the behavior of users in the cryptocurrency market, thus leading to meaningful implications for policymakers, investors, and managers dealing with the cryptocurrency market.
Christopher Copeland, Mikaela Wallin, Thomas J. Holt
The development of the Darknet as a parallel network to the Web in the 21st century has facilitated illegal trafficking in small arms, as defined by the United Nations. The authors have used investigative research methodologies to observe six weapon sale sites on the Darknet over a six-month period to identify sellers of firearms, the type and caliber of weapons for sale, manufacturer, price in Bitcoin, and the principle national origins of the firearms. This is the first study of its type to explore the illegal sale of firearms on the Darknet. This evidence can be used by law enforcement to intercept and shut down said sites and provide insight to the nature of the illegal arms trade on the Darknet.
Adnan Qayyum, Junaid Qadir, Muhammad Umar Janjua, Falak Sher
In recent years, `fake news' has become a global issue that raises unprecedented challenges for human society and democracy. This problem has arisen due to the emergence of various concomitant phenomena such as (1) the digitization of human life and the ease of disseminating news through social networking applications (such as Facebook and WhatsApp); (2) the availability of `big data' that allows customization of news feeds and the creation of polarized so-called `filter-bubbles'; and (3) the rapid progress made by generative machine learning (ML) and deep learning (DL) algorithms in creating realistic-looking yet fake digital content (such as text, images, and videos). There is a crucial need to combat the rampant rise of fake news and disinformation. In this paper, we propose a high-level overview of a blockchain-based framework for fake news prevention and highlight the various design issues and consideration of such a blockchain-based framework for tackling fake news.
21. yüzyıl bilgi ve iletişim teknolojilerinde önemli gelişmelere sahne olmuştur. Özellikle iletişim teknolojilerinde yaşanan kayda değer gelişmeler sonucu akıllı telefonların ortaya çıkması, interneti insanların günlük yaşantılarında sürekli kullandıkları bir teknoloji haline getirmiştir. Bu gelişmeler hayatın pek çok alanını değiştirdiği gibi ekonomik faaliyetleri de değiştirmiş ve bu faaliyetleri internet ortamına taşımıştır. Günümüzde bankacılık işlemlerinden, alışverişe kadar pek çok faaliyet internet üzerinden kolaylıkla yapılabilmektedir. Ancak internetin sunduğu bu kolaylıklar, güvenlik açıkları, verilerin çalınması gibi pek çok sorunu da beraberinde getirmektedir. Bu noktada blockchain teknolojisinin güvenlik açıklarına karşı korumalı ve bir ağ üzerinde şifrelenen verilerin yönetimini sağlayan dağınık bir veri tabanı oluşu, bu kronikleşmiş sorunların çözülmesinin yanı sıra günümüz ekonomilerinde yaşanan pek çok soruna da çözümler sunmaktadır. Bu çerçevede blockchain tabanlı ekosistemlerin oluşturulması amacıyla kamu/özel destekli pek çok platform hali hazırda çalışmalar yürütmektedir. Bu çalışmada, Blockchain’in altyapısını oluşturan teknoloji hakkında bilgi verilmiş ve bu teknolojinin kullanım alanları doğrultusunda uygulama alanları incelenmiştir.
This paper deals with design of the alternative secure Blockchain network framework to prevent damages from an attacker. The concept of the strategic alliance of the management is applied on the top of the recent developed stochastic game framework. This new enhanced hybrid theoretical model has been developed based on the combination of the conventional game theory, the fluctuation theory and the Blockchain Governance Game to find best strategies towards preparation for preventing a network malfunction from an attacker by making the strategic alliance with other genuine miners. Analytically tractable results for decision making parameters are fully obtained which enable to predict the moment for operations and deliver the optimal number of the alliance with other nodes to protect the Blockchain network. This research helps for whom considers the initial coin offering or launching new blockchain based services with enhancing the security features by alliance with the trusted miners within the decentralized network.
Bitcoin is a cryptocurrency that features a distributed, decentralized and trustworthy mechanism, which has made Bitcoin a popular global transaction platform. The transaction efficiency among nations and the privacy benefiting from address anonymity of the Bitcoin network have attracted many activities such as payments, investments, gambling, and even money laundering in the past decade. Unfortunately, some criminal behaviors which took advantage of this platform were not identified. This has discouraged many governments to support cryptocurrency. Thus, the capability to identify criminal addresses becomes an important issue in the cryptocurrency network. In this paper, we propose new features in addition to those commonly used in the literature to build a classification model for detecting abnormality of Bitcoin network addresses. These features include various high orders of moments of transaction time (represented by block height) which summarizes the transaction history in an efficient way. The extracted features are trained by supervised machine learning methods on a labeling category data set. The experimental evaluation shows that these features have improved the performance of Bitcoin address classification significantly. We evaluate the results under eight classifiers and achieve the highest Micro-Fl /Macro-F1 of 87% /86% with LightGBM.